High School BeginnerModule B5Lesson 7 of 7

B5.7 Web Safety Analysis Lab

Practice reviewing a fake web safety case by connecting browser clues, web address clues, HTTPS limits, form behavior, redirects, downloads, and safe research habits into one defensive decision.

Lesson Progress

Web Safety Analysis Lab

High School BeginnerB5: Web Basics and Browser Safety • Lesson 7 of 7

100% complete

Readiness Check

Before You Start

0/3 ready

Professional Hook

Defenders do not decide from one clue

A web safety problem rarely has only one clue. A defender may need to compare the URL, browser warnings, redirects, certificate context, forms, download prompts, cookies, session behavior, user reports, and trusted source paths. The goal is not to be dramatic. The goal is to protect people while making a careful, evidence-based decision.

Lab safety boundary: use only the fake evidence on this page. Do not visit, test, scan, submit information to, or download from real suspicious pages.

Learning Objective

Review a fake web safety case using browser clues, URL clues, certificate signals, form behavior, download warnings, and source quality.

Learning Objective

Separate confirmed evidence from guesses before making a safety decision.

Learning Objective

Choose a safe defensive response when a webpage, download, redirect, or login request feels questionable.

Learning Objective

Write a short professional web safety summary that avoids panic, blame, and unsafe testing.

Why This Matters

Web decisions affect accounts, devices, data, and trust

A single unsafe web decision can expose account information, lead to unwanted downloads, confuse students with fake resources, or create extra work for teachers and technology staff. Safe analysis helps students pause before acting, document what happened, and choose a trusted path forward.

Visual Diagram

Web Safety Analysis Workflow

This lab pulls together the full B5 module: browsers, URLs, HTTPS, forms, cookies, sessions, downloads, redirects, browser warnings, and safe research habits.

1

Identify the task

What was the student trying to do: research, log in, download, submit a form, or visit a class resource?

2

Check address clues

Review the fake URL, domain, spelling, path, and whether the page matches the expected organization.

3

Review browser signals

Look for warnings, certificate issues, redirects, pop-ups, strange forms, or unexpected permission requests.

4

Separate facts from guesses

Write only what the evidence shows. Mark missing context as unknown instead of assuming.

5

Choose the safe response

Stop risky actions, use trusted sources, report through the right channel, and ask trusted help when needed.

Fake Screenshot

Browser Safety Case Board

This is a fake training case. It is not a real website, phishing page, download, or school portal. Students should analyze the clues without testing real suspicious pages.

https://student-help-center.example-login.training/verify

Fake Webpage Preview

Student Account Verification Required

The fake page claims a class research article is locked until the student verifies their school email, password, phone number, and recovery code.

School email: Do not enter real information
Password: Do not enter real information
Phone number: Do not enter real information
Recovery code: Do not enter real information

Safety Concern

The page asks for too much sensitive account information and is not reached through the official fake school portal.

Safer Action

Close the page, use the teacher-provided link in the class LMS, and ask trusted help if the student already entered information.

Professional Note

The summary should describe evidence, not accuse anyone or test the page further.

Core Concept

Use an evidence bundle, not a feeling

Web safety analysis is stronger when you combine several clues. A page can look polished but still ask for risky information. A page can use HTTPS but still be the wrong domain. A browser warning may be enough to stop, but a professional summary should still explain what evidence was observed and what safe action should happen next.

Key Vocabulary

Words for Web Safety Analysis

Web safety analysis

A careful review of webpage clues, browser behavior, user reports, and fake evidence to decide the safest defensive response.

Evidence bundle

A group of clues used together, such as a URL, browser warning, form request, redirect path, and user report.

Confirmed fact

A detail clearly shown by the evidence, not something assumed or guessed.

Unverified claim

A statement that might be true but needs more trusted evidence before it should be used for a conclusion.

Safe recommendation

A defensive next step that protects users, devices, accounts, and privacy without testing real suspicious content.

Escalation

Asking a trusted adult, teacher, guardian, or school technology staff member for help when the issue could affect safety or school systems.

Technical Breakdown

Evidence Bundle Review

Evidence type

Fake URL

https://student-help-center.example-login.training/verify
The address looks related to school help, but the domain is not the official school portal in the fake scenario.

Evidence type

Browser behavior

Redirected twice before showing a login form
Redirects are not automatically unsafe, but unexpected redirects before a login page deserve caution.

Evidence type

Form request

Asks for school email, password, phone number, and recovery code
This is too much information for a basic resource page. The safest action is to stop and verify.

Evidence type

Source quality

No school branding policy link, no teacher-provided URL, no help desk reference
The page does not provide enough trusted context to use it for account entry.

Evidence type

Safe alternative

Teacher posted the official portal in the class LMS
Use the known trusted path instead of the questionable page.

Confirmed Facts

  • The fake page asks for sensitive school account information.
  • The fake URL is not the teacher-provided portal path.
  • The fake case includes unexpected redirects before the form appears.

Gaps / Unknowns

  • We do not know who created the fake page from the evidence shown.
  • We do not know whether any real student entered information.
  • We should not test the fake page as if it were real.

Safe Recommendations

  • Use the official teacher-provided portal link instead.
  • Report the issue through a trusted school channel.
  • Ask trusted staff for help if any account information was shared.

Common Mistakes

Mistakes to avoid in this lab

Clicking through warnings because a page looks important or urgent.
Treating HTTPS as proof that a webpage is safe, accurate, or official.
Entering school, personal, or account information into a page that has not been verified.
Downloading a file just to find out whether it is safe.
Making a dramatic conclusion from one clue without comparing the full evidence bundle.
Trying to test a real suspicious website instead of using safe, fake training examples and trusted help.

Safe Defensive Lab

Write a fake web safety triage note

Fake Student Report

A research page asked me to verify my school account

The student says they were looking for a browser safety article, clicked a search result, saw two redirects, and then reached a form asking for school email, password, phone number, and a recovery code.

Your Defensive Task

  • List three confirmed facts from the fake evidence.
  • List two unknowns that need trusted confirmation.
  • Write one safe recommendation for the student.
  • Explain who should help if information was entered.

Fake Dashboard

Fake Web Safety Review Dashboard

Training-only dashboard using fake evidence from a fictional web safety case.

Evidence items

5

URL, redirects, form request, source quality, trusted alternative.

Risk signals

3

Sensitive form, wrong trusted path, unexpected redirects.

Safe action

Stop

Do not submit information or test the page further.

Fake SOC Alert

Sensitive account form on unverified page

Source: Fake Browser Safety Training • Time: 2:42 PM

High Severity
A fake page that was not reached through the official class portal requested school email, password, phone number, and recovery code before showing a research article.
Defensive recommendation: Do not enter information. Close the page, use the teacher-provided class portal link, and ask a teacher, guardian, or school technology staff member for help if any information was shared.

Fake Log Panel

Fake Web Safety Case Logs

training-log-viewer.log
14:34:08 SEARCH query='browser safety article for class poster' source='training-browser'
14:35:22 RESULT_OPENED title='Student Help Center Article' domain='example-login.training'
14:35:25 REDIRECT from='/article' to='/verify' status='unexpected'
14:35:30 FORM_DISPLAYED fields='email,password,phone,recovery-code'
14:35:34 USER_ACTION action='stopped before submitting information'
14:36:10 SAFE_PATH selected='teacher-provided LMS resource link'
14:37:02 REPORT_DRAFTED summary='unverified page requested sensitive account details'

Training note: this is fake data for defensive analysis practice only.

Analyze the Evidence

What is the safest conclusion?

The fake page asks for school email, password, phone number, and a recovery code.
The fake page was not reached through the official teacher-provided portal path.
The page appeared after unexpected redirects.
The student has access to a trusted class LMS link as a safer alternative.

Which conclusion is most responsible?

Scenario Decision Lab

A classmate says the page might be real

A classmate says the fake verification page might be real because it has a lock icon and looks professional. They want to enter a school email and password to test whether it works.

Defender Habits

B5.7 Defender Checklist

Check Your Understanding

B5.7 Mini Scored Quiz

Choose your answers first. Explanations appear only after submission.

1. What is the safest first response when a fake research page unexpectedly asks for a school password?

2. Why is HTTPS not enough to prove a webpage is safe?

3. Which statement is a confirmed fact from evidence?

4. What should a student do with a suspicious download prompt during a school project?

5. What makes a web safety summary professional?

Portfolio Prompt

Create a Web Safety Analysis Report

Write a short report for the fake web safety case. Include the situation, three evidence facts, two unknowns, the risk, and the safest recommendation.

Use calm language: observed, requested, unclear, recommend.
Do not include real private information, real links, or instructions to test suspicious pages.
End with a trusted-help step for students who feel unsafe or already shared information.

Key Takeaways

What You Should Remember

1.Web safety analysis uses multiple clues together, not one clue alone.
2.HTTPS is important, but it does not prove that a page is official or safe for account entry.
3.Unexpected redirects, risky forms, suspicious downloads, and browser warnings should make students stop and verify.
4.Professional summaries separate confirmed facts, gaps, risk, and safe recommendations.
5.Students should use trusted sources and trusted adults instead of testing real suspicious websites.

Navigation

Finish Module B5